The European Commission’s AI Office, together with national market surveillance authorities, began enforcing the EU AI Act on August 2, two years after the law entered into force. Chatbots must now identify themselves as AI. Deepfakes and other synthetic images, video, and audio must be labeled, and machine-readable marks are required on AI-generated or altered content, using a set of icons the Commission has published for the purpose.

Enforcement teeth arrive with the transparency rules. The AI Office can now investigate GPAI providers, order fixes, and impose fines up to €15 million or 3% of global annual turnover, with a €750,000 ceiling for EU institutions and proportional penalties for SMEs. GPAI providers must document training data, publish a sufficiently detailed summary of training content, and adopt a copyright policy. Models posing systemic risks pick up additional obligations covering CBRN, loss of control, cyber offense, and manipulation.

What Brussels didn’t switch on is at least as revealing. The AI Omnibus pushed the general high-risk regime to December 2, 2027, and high-risk systems embedded in regulated products to August 2, 2028. GPAI obligations technically applied in 2025, but only now do they carry enforcement weight. A separate prohibition on AI-generated CSAM and non-consensual sexually explicit content takes effect December 2, 2026.

Supporting the AI Office is a 60-member Scientific Panel that recently held its first meeting, with Oxford’s Professor Alessandro Abate named Lead Scientific Adviser.

Tech Policy Press notes the powers arrive days after the first reported autonomous AI agent carrying out an unexpected cyber operation. The sequencing recalls GDPR’s 2018 debut, when the toughest cases landed on regulators before the ink was dry. Brussels wanted transparency first and hard cases later. The hard cases showed up early.

Sources

Sources